Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748.
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-056 | patch vendor advisory |
http://www.securityfocus.com/bid/74996 | broken link third party advisory vdb entry |
http://www.zerodayinitiative.com/advisories/ZDI-15-377 | third party advisory vdb entry |
http://www.securitytracker.com/id/1032521 | broken link third party advisory vdb entry |